A
A
Andrew2018-11-02 00:21:05
Digital certificates
Andrew, 2018-11-02 00:21:05

Subject Alternative Name (SAN) SSL certificate, where are the strange names coming from?

I regularly study records and information about certificates from https://crt.sh
For example, according to Habr.ru https://crt.sh/?id=282759903
In section X509v3 Subject Alternative Name:
DNS:habr.ru
DNS:www are specified. habr.ru
Everything seems to be clear here, and the Subject section specifies organizationalUnitName = PositiveSSL
However, the same certificates that have organizationalUnitName = PositiveSSL Multi-Domain in the Subject section
Those have a complete scatter of names, like dns, the resource has one name, and it is working , but the X509v3 Subject Alternative Name: section is full of different resource names that, when visited, visually have nothing to do with the main name at all.
As far as I understand, alternative names are created when creating a certificate, conditionally, by the owner, or after all, you should not trust the records from the X509v3 Subject Alternative Name, should you not associate them with the main domain?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
D
DevMan, 2018-11-02
@AndrewFoma

multi-domain certificates allow you to serve completely different domains.
and add them as needed.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question